Multi-Actor Espionage Campaign Weaponizes Balochistan Police Complaint Management Portal (PlugX, ShadowPad, Cobalt Strike, Remcos/TAG-179)

Multi-Actor Espionage Campaign Weaponizes Balochistan Police (TL-2026-1239), also tracked as One Target, Two Flags, is a high-severity advanced persistent threat campaign, first published 2026-07-11. It is attributed to TAG-179 (China, India) with high confidence, affects Balochistan Police Complaint Management System (CMS), maps to 38 MITRE ATT&CK techniques (T1005, T1008, T1016), and is covered by 9 detection rules and 43 indicators of compromise.

Key facts for TL-2026-1239

Threat ID
TL-2026-1239
Also known as
One Target, Two Flags, Balochistan Police CMS Compromise
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-07-11
Last reviewed
2026-07-11
Attribution
TAG-179
Attribution confidence
HIGH
Nation-state nexus
China, India
Motivation
ESPIONAGE
Target sectors
government administration, police - law enforcement, defense, foreignaffairs, intelligence, academicresearch, telecoms, ngo, manufacturing, criticalinfrastructure
Target regions
pakistan, South Asia, Southeast Asia, 143 - Central Asia, East Asia, Middle East, Southeast Europe
Detection rules
9
Indicators of compromise
43

Malware and tooling in Multi-Actor Espionage Campaign Weaponizes Balochistan Police

Malware and tooling: AsyncRAT, PlugX, Remcos, ShadowPad, Cobalt Strike

SentinelLABS documented converging China-nexus (PlugX, ShadowPad, Cobalt Strike) and India-nexus (TAG-179/Remcos, overlapping Mysterious Elephant/APT-C-08/SideWinder/Confucius/Bitter TTPs) espionage clusters that separately compromised Pakistani law enforcement networks, including Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad Police, and the Punjab Safe Cities Authority, between February 2024 and April 2026. The China-nexus actor weaponized the public-facing Balochistan Police Complaint Management System (cms.balochistanpolice.gov.pk) by uploading a custom implant (cms_plugin.exe) disguised as a portal update, compromising both police staff and citizen users.

How Multi-Actor Espionage Campaign Weaponizes Balochistan Police works

SentinelOne's SentinelLABS (researcher Aleksandar Milenkoski) published "One Target, Two Flags: Rival Espionage Actors Converge On Pakistani Law Enforcement," documenting a multi-year, multi-actor cyberespionage campaign against Pakistani police infrastructure. Two distinct, unrelated nation-state-nexus actor clusters independently compromised overlapping victim infrastructure: a suspected China-nexus cluster deploying PlugX (Feb 27-Sep 28, 2024), ShadowPad (Nov 5-Dec 1, 2024), and Cobalt Strike (Oct 12, 2024-Dec 2025); and a suspected India-nexus cluster tracked by Recorded Future as TAG-179, overlapping with Kaspersky's Mysterious Elephant (APT-K-47/APT-C-08) and related SideWinder/Confucius/Bitter TTP-sharing groups, deploying Remcos RAT (Jan 13-Apr 9, 2026) via a decoy document themed around Afghan Citizen Card (ACC) repatriation operations.

The most significant new development is the China-nexus actor's compromise of the Balochistan Police Complaint Management System (CMS), a public-facing web application at cms.balochistanpolice.gov.pk that is used both by police staff (restricted ps-[district] logins) and by ordinary citizens filing complaints. The attackers uploaded two variants of a custom implant named cms_plugin.exe to the portal's client-scripts directory, disguised as a routine portal update: a Rust-based stager and a .NET executable masquerading as the legitimate Chinese antivirus process 360Safe.exe (Qihoo 360). The .NET variant reflectively loads an embedded AsyncRAT client that calls back to 41.216.188.140. Compromised Chinese-language PDB paths (D:\codedome\case\six\Client\Client2\obj\Debug\Client2.pdb), the term "xinshi" (new variant), and Simplified Chinese log strings indicate a Chinese-speaking developer.

Beyond the CMS, the China-nexus actors compromised Balochistan Police web servers hosting the First Information Report (FIR) system, the Human Resource Management Information System (HRMIS), the Anti-Vehicle Lifting System (AVLS), HotelEye (hotel/tenant tracking with NADRA national-ID integration), the Criminal Record Management System (CRMS, biometric records), the Tenant Registration System (TRS), two network appliances, and a Fortinet FortiMail email gateway appliance — all part of an EU-supported "Smart Police Station" digitalization initiative that was turned into an intelligence-collection vector.

SentinelLABS assesses with high confidence that the China-nexus activity is motivated by Beijing's concern for the safety of Chinese nationals connected to the China-Pakistan Economic Corridor (CPEC), following deadly attacks on Chinese personnel including the October 2024 Karachi airport bombing and a March 2024 suicide bombing, both attributed to the Balochistan Liberation Army (BLA); China sought independent insight into Pakistan's internal security posture ahead of a January 2026 China-Pakistan counterterrorism coordination agreement. The India-nexus/TAG-179 activity is assessed as driven by the long-running India-Pakistan security rivalry and interest in Balochistan's insurgency dynamics and cross-border militancy dynamics. Victimology for the broader PlugX/ShadowPad/Cobalt Strike and TAG-179/Mysterious Elephant clusters spans government, foreign affairs, defense, intelligence, academic/research, telecommunications, NGO, and manufacturing targets across South Asia (India, Bangladesh, Nepal, Sri Lanka), Southeast Asia (Vietnam, Thailand, Philippines), Central Asia (Kazakhstan, Tajikistan), East Asia (China, Taiwan — including Tibetan Buddhist organizations), the Middle East/Arabian Peninsula (Saudi Arabia, UAE, Iran), and Southeast Europe.

No CVEs were disclosed in the source reporting; initial access to the CMS and internal networks appears to rely on compromised credentials, direct web-application upload access, and trust in a public-facing government portal rather than a specific software vulnerability.

MITRE ATT&CK techniques used in TL-2026-1239

Collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection; T1123 Audio Capture

Command and Control

T1008 Fallback Channels; T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Discovery

T1016 System Network Configuration Discovery; T1087 Account Discovery; T1518 Software Discovery

Exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading

Credential Access

T1056.001 Keylogging; T1110 Brute Force; T1187 Forced Authentication

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204.002 Malicious File

Initial Access

T1078 Valid Accounts; T1189 Drive-by Compromise; T1199 Trusted Relationship; T1566.001 Spearphishing Attachment

Privilege Escalation

T1078 Valid Accounts

Persistence

T1505.003 Web Shell; T1547 Boot or Logon Autostart Execution; T1554 Compromise Host Software Binary

Impact

T1565 Data Manipulation

Resource Development

T1583.004 Server; T1587.001 Malware

Reconnaissance

T1591 Gather Victim Org Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Multi-Actor Espionage Campaign Weaponizes Balochistan Police

  • Balochistan Police — Complaint Management System (CMS)
    Vulnerable versions: cms.balochistanpolice.gov.pk (all versions prior to remediation)
  • Balochistan Police — First Information Report (FIR) System
    Vulnerable versions: deployed instance, 2024-2026
  • Balochistan Police — Human Resource Management Information System (HRMIS)
    Vulnerable versions: deployed instance, 2024-2026
  • Balochistan Police — Anti-Vehicle Lifting System (AVLS)
    Vulnerable versions: deployed instance, 2024-2026
  • Balochistan Police — HotelEye (hotel/tenant tracking, NADRA-integrated)
    Vulnerable versions: deployed instance, 2024-2026
  • Balochistan Police — Criminal Record Management System (CRMS)
    Vulnerable versions: deployed instance, 2024-2026
  • Balochistan Police — Tenant Registration System (TRS)
    Vulnerable versions: deployed instance, 2024-2026
  • Fortinet — FortiMail
    Vulnerable versions: appliance deployed as Balochistan Police primary email gateway

Remediation for Multi-Actor Espionage Campaign Weaponizes Balochistan Police

Immediate actions

  • Block identified C2 IPs (172.111.233.36/96/12/105/26, 172.94.9.49/43/19, 45.74.6.17, 45.125.32.218, 142.171.183.8, 193.42.25.65, 41.216.188.140, 89.31.121.220) at network perimeter
  • Remove cms_plugin.exe and 360Safe.exe-masquerading binaries from all Balochistan Police CMS servers and endpoints
  • Force credential resets for all ps-[district] police staff CMS accounts and FortiMail administrative accounts
  • Isolate and forensically image the two compromised network appliances and the FortiMail gateway

Workarounds

  • Digitally sign and verify all client-side downloads served from government portals before user execution
  • Disable direct file upload/execution capability on public complaint-management web servers pending network segmentation

Longer-term hardening

  • Segment citizen-facing web applications (CMS, complaint portals) from internal law-enforcement networks and databases
  • Implement mandatory multi-factor authentication for all law-enforcement portal and email-gateway logins
  • Deploy application-layer intrusion detection and file-integrity monitoring on all public-facing government web servers
  • Establish a secure software update/signing process for portal client-side executables to prevent trojanized 'update' uploads
  • Conduct dark-web credential exposure monitoring for police-domain accounts

Weaknesses (CWE) in Multi-Actor Espionage Campaign Weaponizes Balochistan Police

CWE-506, CWE-829, CWE-345

Timeline of Multi-Actor Espionage Campaign Weaponizes Balochistan Police

  • China-nexus actor begins PlugX backdoor deployment against Pakistani law enforcement networks.
  • March 2024 suicide bombing targeting Chinese nationals in Pakistan, attributed to the Balochistan Liberation Army, heightening Chinese security interest in the region.
  • Compromise of Balochistan Police infrastructure, including the Complaint Management System, begins (per SentinelLABS observed range June 2024-April 2026).
  • Observed PlugX C2 activity against Pakistani law enforcement ends.
  • Chinese Ambassador issues statement on Pakistan security situation following attacks on Chinese nationals.
  • China-nexus actor begins Cobalt Strike operations against multiple Pakistani law-enforcement-linked targets.
  • Karachi airport attack by the Balochistan Liberation Army targeting Chinese nationals, reinforcing Beijing's motivation for independent security intelligence collection in Pakistan.
  • China-nexus actor deploys ShadowPad backdoor against Pakistani law enforcement infrastructure.
  • Custom cms_plugin.exe implants (Rust stager and .NET/360Safe.exe-masquerading variant) uploaded to the Balochistan Police CMS client-scripts directory, disguised as a routine portal update.
  • Observed ShadowPad C2 activity ends.
  • First phase of observed Cobalt Strike C2 activity against Balochistan Police-linked infrastructure ends (broader Cobalt Strike activity continues through December 2025).
  • TAG-179 (India-nexus) begins Remcos RAT campaign against Pakistani law enforcement, using an Afghan Citizen Card repatriation-themed decoy document.
  • China and Pakistan reach a counterterrorism coordination agreement, aligning with China's continued interest in independent security intelligence on Pakistan.
  • Observed TAG-179 Remcos C2 activity against Pakistani law enforcement ends.
  • SentinelOne SentinelLABS publishes "One Target, Two Flags," documenting the converging China-nexus and India-nexus campaigns against Pakistani law enforcement, including the Balochistan Police CMS weaponization.
  • The Hacker News and other outlets publish coverage of the SentinelLABS findings, amplifying public disclosure of the CMS portal weaponization.

Sources cited for Multi-Actor Espionage Campaign Weaponizes Balochistan Police

Threats related to Multi-Actor Espionage Campaign Weaponizes Balochistan Police

Detection coverage for TL-2026-1239

As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1239 across Splunk SPL, Microsoft KQL and Sigma, covering 43 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1239

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats